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AMENDMENT TO CLAIMS 

Please amend the following claims as indicated: 

1. (Previously Presented) An apparatus for auditing security of a remote computer 
system, comprising: 

a. a secure application server in communication with a global computer network and 
programmed to receive selectively security audit instruction data from the remote 
computer system via the global computer network; 

b. a plurality of scanning machines in communication with the global computer 
network and programmed to execute selectively a security audit scan of the 
remote computer system via the global computer network, each scanning machine 
capable of conducting multiple types of security assessments; and 

c. a central computer, having a memory, configured as a database server and as a 
scheduler, in communication with the secure application server and the plurality 
of scanning machines, programmed to perform operations comprising: 

a. evaluating a database to determine if the security audit scan is currently 
scheduled to be run on one of the scanning machines; 

b- determining which of the plurality of scanning machines is available to 
perform the security audit scan by examining a schedule for each scanning 
machine to identify certain ones of the scanning machines that are 
conducting another security audit scan or are scheduled to conduct another 
security audit scan, the available scanning machines comprising all of the 
scanning machines except for the certain scanning machines; 

c. copying scan-related information into one of the available scanning 
machines and instructing the scanning machine to begin the security audit 
scan; and 

d, recording the results of the security audit scan in the memory. 

2. (Original) The apparatus of Claim 1» wherein the secure application server comprises 
a Web server. 
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3. (Previously Presented) The apparatus of Claim 1, wherein the central computer is 
further programmed to issue a notification the security audit scan is commencing. 

4. (Previously Presented) The apparatus of Clam 1, wherein the central computer is 
further programmed to update the database to indicate that the security audit scan is complete. 

5. (Previously Presented) The apparatus of Claim 1, wherein the central computer is 
further programmed to send a signal representing completion of the security audit scan. 

6. (Previously Presented) The apparatus of Claim 1, wherein when the central computer 
performs the operation in which the central computer records the results of the security audit 
scan, the central computer also copies the results to the database and copies a report to a file 
system on a database machine when the security audit scan is complete. 
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7. (Previously Presented) A method of auditing security of a remote computer system, 
comprising the steps of: 

a. receiving an instruction to perform a security audit scan on the remote computer 

system; 

b. determining which of a plurality of scanning machines is available to perform the 
security audit scan by examining a schedule for each of the scanning machines to 
identify certain ones of the scanning machines that are conducting another 
security audit scan or are scheduled to conduct another security audit scan, the 
available scanning machines comprising all of the scanning machines except for 
the certain scanning machines, and wherein each of the scanning machines is 
capable of conducting a plurality of security assessments; and 

c. instructing one of the available scanning machines to access the remote computer 
system via a global computer network to-perform the security audit scan of the 
remote computer system. 

8* (Previously Presented) The method of Claim 7, further comprising the step of 
recording a result of the security audit scan in a computer memory. 

9. (Canceled) 
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10. (Currently Amended) A method of auditing computer system security, comprising 
the steps of: 

a. receiving a schedule request for a security audit scan of a remote computer 
system, wherein the security audit scan of the remote computer system is 
scheduled to be conducted after the schedule request is received; 

b. recording the scheduled security audit scan in a database; 

c. accessing the database to determine when the scheduled security audit 
scan of the remote computer system is to be executed; 

d. in response to a determination that the scheduled security audit scan of the remote 
computer system is to be executed in a predetermined period of time, performing 
the following steps: 

i. determining which of a plurality of sca nniTifl ma chines is available to 

perform the scheduled security audit scan b y camming a sched ule for 

each of the scanning machines to identify certain ones of the scanning 

machines that are conducting another security audit scan or are scheduled 
to conduct another security audit scan; 

ii. copying security audit scan data into a scanning system; 

iij, causing the scanning system to establish communication with the remote 
computer system via a global computer network; and 

ivtii. causing the scanning system to execute the scheduled security audit scan 
of the remote computer system via the global computer network. 

11. (Previously Presented) The method of Claim 7, further comprising the step of 
receiving at the available scanning machine scan related information for the security audit scan 
of the remote computer system. 

12. (Previously Presented) The method of Claim 11, wherein the scan related 
information comprises at least one security assessment to be conducted during the security audit 
scan. 
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13. (Previously Presented) The method of Claim 11, wherein the scan related 
information comprises an identity of at least one remote computer system upon which to conduct 
the security audit scan. 

14. (Previously Presented) The method of Claim 7, further comprising the step of 
sending a message to a user interface that the security audit scan is being conducted. 

15. (Previously Presented) The method of Claim 7, wherein the security audit scan 
comprises a vulnerability assessment. 

16. (Previously Presented) The method of Claim 7, wherein the security audit scan 
comprises a penetration study. 

17. (Previously Presented) The method of Claim 7, further comprising the step of 
recording a result of the security audit scan in a database. 

18. (Previously Presented) The method of Claim 17, wherein the result comprises at 
least one vulnerability of the remote computer system detected by the available scanning 
machine during the security audit scan. 

19. (Previously Presented) The method of Claim 18, wherein the result further 
comprises a list of at least one security assessment conducted during the security audit scan. 

20. (Previously Presented) The method of Claim 7, further comprising the step of 
determining if the available scanning machine is currently conducting the security audit scan on 
the remote computer system. 

21 (Previously Presented) The method of Claim 7, further comprising the step of 
receiving from the available scanning machine a notification at a central computer that the 
security audit scan of the remote computer system is complete. 

22. (Previously Presented) The method of Claim 21, further comprising the step of 
reporting at least one result of the security audit scan to a user interface. 
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23. (Previously Presented) The method of Claim 22, wherein the at least one result of 
the security audit scan is reported in response to receiving the notification at the central computer 
that the security audit scan is complete. 

24. (Previously Presented) The method of Claim 10, further comprising the step of 
transmitting a message to a user interface that indicates a result of the scheduled security audit 
scan. 

25. (Previously Presented) The method of Claim 10, further comprising the step of 
storing a result of the scheduled security audit scan of the remote computer system in the 
database. 

26. (Previously Presented) The method of Claim 25, wherein the result is used for a 
statistical analysis of security on the remote computer system. 

27. (Previously Presented) The method of Claim 10, further comprising the step of 
determining which of a plurality of scanning systems is available to perform the scheduled 
security audit scan by examining a schedule of each of the scanning systems to identify certain 
ones of the scanning systems that are conducting another security audit scan or are scheduled to 
conduct another security audit scan, the available scanning systems comprising all of the 
scanning systems except for the certain scanning systems. 

28. (Previously Presented) The method of Claim 10, further comprising the step of 
examining the scanning system to determine if the scheduled security audit scan is in the process 
of being conducted on the remote computer system. 

29. (Previously Presented) The method of Claim 10, wherein the security audit scan data 
comprises at least one security assessment to be conducted during the scheduled security audit 
scan. 

30. (Previously Presented) The method of Claim 10, wherein the security audit scan data 
comprises an identity of at least one remote computer system upon which to conduct the 
scheduled security audit scan* 
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31. (Previously Presented) The method of Claim 10, farther comprising the step of 
sending a message to a user interface prior to the commencement of the scheduled security audit 
scan. 

32. (Previously Presented) The method of Claim 10, further comprising the step of 
storing a result of the scheduled security audit scan of the remote computer system. 

33. (Previously Presented) The method of Claim 32, wherein the result comprises at 
least one vulnerability of the remote computer system detected by the scanning system during the 
scheduled security audit scan. 

34. (Previously Presented) The method of Claim 33, wherein the result further 
comprises a list of at least one security assessment conducted during the scheduled security audit 
scan. 

35. (Previously Presented) The method of Claim 10, further comprising the step of 
determining if a request for an immediate security audit scan of one of a plurality of computer 
systems has been received in response to a determination that the scheduled security audit scan 
of the remote computer system will be executed outside of the predetermined period of time, 

36. (Previously Presented) The method of Claim 10, further comprising the step of 
receiving from the scanning system a notification at a central computer that the scheduled 
security audit scan of the remote computer system is complete. 
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37. (Previously Presented) A method of conducting a security audit scan of a remote 
computer system comprising the steps of : 

a. receiving a request to schedule the security audit scan of the remote computer 
system; 

b. recording a scheduled security audit scan in a database; 

c. accessing the database to determine when the scheduled security audit scan of the 
remote computer system is to be executed; and 

d. in response to a determination that the scheduled security audit scan of the remote 
computer system is to be executed, performing the following steps: 

1. determining which of a plurality of scanning machines is available to 
perform the scheduled security audit scan by examining a schedule for 
each of the scanning machines to identify certain ones of the scanning 
machines that are conducting another security audit scan or are scheduled 
to conduct another security audit scan; and 

2. causing one of the available scanning machines to access the remote 
computer system and execute the scheduled security audit scan. 

38. (Previously Presented) The method of Claim 37, further comprising the step of 
receiving at the available scanning machine scan related information from a central computer for 
the scheduled security audit scan of the remote computer system, 

39. (Previously Presented) The method of Claim 38, wherein the scan related 
information comprises at least one security assessment to be conducted during the scheduled 
security audit scan. 

40. (Previously Presented) The method of Claim 37, further comprising the step of 
sending a message to a user interface that the scheduled security audit scan is being conducted* 

41. (Previously Presented) The method of Claim 37, wherein the scheduled security 
audit scan comprises a vulnerability assessment. 

42. (Previously Presented) The method of Claim 37, further comprising the step of 
recording a result of the scheduled security audit scan in the database. 



10 



PAGE 17/27 * RCVD AT 5/312005 3:58:31 PM [Eastern Daylight Time] * SVR:USPT0-EFXRF-1/1 0 * DNIS:8729306 * CSID:404 572 5145 * DURATION (mm-ss):08-04 



MOY 09 2085 16 = 05 FR KING & SPRLDING LLP 404 572 5145 TO 6527«05456tt 10504 P. 18/27 



Application No. 09/592,404 

43. (Previously Presented) The method of Claim 42, wherein the result comprises at 
least one vulnerability of the remote computer system detected by the available scanning 
machine during the scheduled security audit scan. 

44. (Previously Presented) The method of Claim 37, further comprising the step of 
examining the available scanning machine to determine if the scheduled security audit scan is in 
the process of being conducted on the remote computer system. 

45. (Previously Presented) The method of Claim 37, further comprising the step of 
receiving from the available scanning machine a notification at a central computer that the 
scheduled security audit scan is complete, 

46. (Previously Presented) The method of Claim 37, further comprising the step of 
reporting at least one result of the scheduled security audit scan to a user interface. 

47. (Previously Presented) The method of Claim 46, wherein the at least one result is 
reported in response to receiving a notification at a central computer that the scheduled security 
audit scan is complete. 
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